logo

LastPass Customer Data Exposed in Klue Supply Chain Attack Using Stolen OAuth Tokens

ID: 02a0959c-801e-52fd-83bc-a85d26f2868c

STIX ID: report--02a0959c-801e-52fd-83bc-a85d26f2868c

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Divya

...
...

LastPass disclosed that a security incident at third-party platform Klue led to compromised OAuth tokens, which attackers used to access limited customer CRM data in LastPass's Salesforce instance (names, emails, phone numbers, addresses, and support/sales records). LastPass states core infrastructure and encrypted password vaults were not impacted, revoked and rotated affected tokens, disabled Klue access, shared IoCs (IPs and domains), and advised customers to audit integrations and enforce strict token and access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.